PT-2026-23458 · Unknown · Rustdesk Client
Erez Kalman
·
Published
2026-03-05
·
Updated
2026-03-05
·
CVE-2026-30793
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RustDesk Client versions through 1.4.5
Description
A Cross-Site Request Forgery (CSRF) issue exists in RustDesk Client on Windows, MacOS, Linux, iOS, and Android. This flaw potentially allows for privilege escalation. The issue is related to the Flutter URI scheme handler and FFI bridge modules, specifically within the files
flutter/lib/common.Dart and src/flutter ffi.Rs, and the routines URI handler for rustdesk://password() and bind.MainSetPermanentPassword().Recommendations
Update RustDesk Client to a version later than 1.4.5.
Exploit
Fix
LPE
Improper Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustdesk Client